Free SPLK-3001 Exam Braindumps (page: 6)

Page 5 of 22

Which of the following are data models used by ES? (Choose all that apply.)

  1. Web
  2. Anomalies
  3. Authentication
  4. Network Traffic

Answer(s): B


Reference:

https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/datamodelsusedbyes/



At what point in the ES installation process should Splunk_TA_ForIndexers.spl be deployed to the indexers?

  1. When adding apps to the deployment server.
  2. Splunk_TA_ForIndexers.spl is installed first.
  3. After installing ES on the search head(s) and running the distributed configuration management tool.
  4. Splunk_TA_ForIndexers.spl is only installed on indexer cluster sites using the cluster master and the
    splunk apply cluster-bundle command.

Answer(s): B


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/Install/InstallTechnologyAdd-ons



Which correlation search feature is used to throttle the creation of notable events?

  1. Schedule priority.
  2. Window interval.
  3. Window duration.
  4. Schedule window.

Answer(s): C


Reference:

https://docs.splunk.com/Documentation/ES/6.1.0/Admin/Configurecorrelationsearches



Both “Recommended Actions” and “Adaptive Response Actions” use adaptive response. How do they differ?

  1. Recommended Actions show a textual description to an analyst, Adaptive Response Actions show them encoded.
  2. Recommended Actions show a list of Adaptive Responses to an analyst, Adaptive Response Actions run them automatically.
  3. Recommended Actions show a list of Adaptive Responses that have already been run, Adaptive Response Actions run them automatically.
  4. Recommended Actions show a list of Adaptive Resposes to an analyst, Adaptive Response Actions run manually with analyst intervention.

Answer(s): D


Reference:

https://docs.splunk.com/Documentation/ES/latest/Admin/Configureadaptiveresponse






Post your Comments and Discuss Splunk® SPLK-3001 exam with other Community members:

SPLK-3001 Discussions & Posts